FINN-Tro:利用数据流推理加速器中的验证间隙
FINN-Tro: Exploiting Verification Gaps in Dataflow Inference Accelerators
浏览论文内容
中文总结 AI 辅助
FINN-Tro攻击利用FINN编译流水线中的验证间隙,在不修改量化模型的情况下,在MVAU层插入硬件木马,通过多种触发模式和载荷配置显著降低推理准确率,揭示了现有验证流程的不足。
中文摘要 AI 辅助
数据流加速器在神经网络推理中的日益普及引入了新的攻击面,而现有的验证方法未能解决这些问题。诸如FINN之类的推理加速框架,将量化神经网络转换为可在FPGA上部署的数据流架构,隐含地假设软件模型与综合后的硬件之间具有语义等价性。在本工作中,我们提出了FINN-Tro攻击,该攻击识别并利用了FINN编译流水线中的一个关键验证间隙,使得在不修改原始量化模型的情况下能够隐蔽地插入硬件木马。该木马被放置在最后一个矩阵-向量激活单元(MVAU)层中,支持两种基于计数器的触发模式,即周期性和持久性,以及三种载荷类型:偏置加法、logit交换和偏置减法,从而产生六种不同的配置。FINN-Tro在部署于PYNQ-Z1板上的MNIST前馈网络和CIFAR-10卷积神经网络上进行了评估。在所评估的配置中,准确率下降范围从0.90%到82.84%,而吞吐量和运行时间与相应的基线设计保持接近。最严重的配置,即持久性偏置加法,将MNIST上的准确率从92.96%降至10.12%,将CIFAR-10上的准确率从84.19%降至10.00%。插入的逻辑引入了适度的实现开销,对于MNIST,最大LUT和FF增加分别为6.71%和7.49%,对于CIFAR-10,分别为2.50%和3.98%。我们的研究结果表明,广泛使用的编译前和编译后验证流程不足以检测此类时间延迟的硬件操纵,从而促使在加速器工具链中需要更强的验证机制。
英文摘要
The growing adoption of dataflow accelerators for neural network inference introduces new attack surfaces that existing verification methodologies fail to address. Inference ac- celeration frameworks such as FINN, which transform quantized neural networks into FPGA-deployable dataflow architectures, implicitly assume semantic equivalence between the software model and the synthesized hardware. In this work, we in- troduce the FINN-Tro attack, which identifies and exploits a critical verification gap in the FINN compilation pipeline that enables stealthy hardware Trojan insertion without modifying the original quantized model. The Trojan is placed in the last Matrix-Vector Activation Unit (MVAU) layer and supports two counter-based trigger modes, periodic and persistent, and three payload types: bias addition, logit swapping, and bias subtraction, resulting in six different configurations. FINN-Tro is evaluated on an MNIST feed-forward network and a CIFAR-10 convolutional neural network deployed on a PYNQ-Z1 board. Across the evaluated configurations, accuracy reductions range from 0.90% to 82.84%, while throughput and runtime remain close to the corresponding baseline designs. The most severe configuration, persistent Bias Addition, reduces accuracy from 92.96% to 10.12% on MNIST and from 84.19% to 10.00% on CIFAR-10. The inserted logic introduces modest implementation overhead, with maximum LUT and FF increases of 6.71% and 7.49% for MNIST, and 2.50% and 3.98% for CIFAR-10, respectively. Our findings reveal that widely used pre- and post- compilation verification flows are insufficient for detecting such temporally delayed hardware manipulations, motivating the need for stronger verification mechanisms in accelerator toolchains.
发表机构
- Bielefeld University of Applied Sciences and Arts (HSBI)(比勒费尔德应用科学与艺术大学)
机构由 AI 辅助整理,请以论文原文为准。